Description
XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2013-1519 Vulnerability (CVE-2013-1519)
WordPress Plugin SyntaxHighlighter Evolved Cross-Site Scripting (3.5.0)
Oracle Database Server CVE-2009-1972 Vulnerability (CVE-2009-1972)
MySQL CVE-2012-1735 Vulnerability (CVE-2012-1735)
WordPress Plugin Viral Quiz Maker-OnionBuzz SQL Injection (1.2.6)